We find the gaps.Then we watch them.
We test your defences the way a real attacker would, then put an AI analyst on your endpoints to catch what comes next — reasoning through every alert and holding for a human before anything irreversible. All EU-hosted, on the model you choose.
Trusted by security and engineering teams across the Nordics
- Vickers
- CleanConsulting
- Vickers
- CleanConsulting
- Vickers
- CleanConsulting
- Vickers
- CleanConsulting
What's at stake
None of this is hypothetical.
Four of the six below are documented incidents you can look up. Two are patterns — written as patterns, because we will not dress an anecdote up as a case study.
Financial impact
What if ransomware locks our systems?
In July 2021 ransomware reached one of Coop Sweden's software suppliers and around 800 stores closed. The tills could not take payment, so the business stopped — and stayed stopped until the systems were rebuilt.
Fraud
What if someone impersonates the CEO by email?
Business email compromise does not look like an attack. Someone who has read enough of your mail knows the nickname the CEO signs off with, which supplier is due to be paid, and when the CFO is travelling. The payment clears before anyone thinks to check.
Client trust
What if the client list leaks?
A leaked client list is not one incident. It is every client relationship at once, and someone has to ring each of them and explain. Every one of those calls is a conversation about whether they stay.
Availability
What if the payment rails go down?
Through spring 2025 both BankID and Swish were repeatedly knocked over by denial-of-service attacks, disruption the Riksbank recorded in its own payments reporting. Neither service was breached. They were merely unavailable — which, for a day, is the same thing.
Deepfake fraud
What if the person on the video call isn't real?
In 2024 an employee at the engineering firm Arup joined a video call with the CFO and several colleagues and authorised fifteen transfers worth about $25 million in a single day. Every face and voice on that call had been generated from public footage.
False confidence
What if the tool everyone trusts can be bypassed?
Exam-monitoring software mandated across more than 200 Danish institutions could be defeated by renaming the browser executable. A control being installed, paid for and reported on says nothing about whether it holds.
Our solutions
One side finds the way in. The other watches it.
An offensive service that finds the routes into your estate, and an EU-hosted detection & response layer that keeps watching them. Each sharpens the other.
Cryvanta PenTest
AI-driven offensive testing, delivered as an engagement.
Our in-house tooling drives the attack; a Cryvanta operator scopes it, verifies every finding by hand, and hands you a report you can act on — not a scanner dump. You get the results, not a tool to run.
- Scoped to your real environment
- AI-run attack, human-verified findings
- Prioritised, actionable reporting
- Findings feed the detection library
Cryvanta AI SOC
An AI analyst desk for detection & response.
Triages, investigates and rules on detections around the clock, with visible brakes before anything irreversible. In early access with design partners today.
- LLM analyst on every finding
- Closed-loop detection engineering
- Windows sensor now · macOS & Linux ahead
- Bring your own model, EU-hosted
The analyst desk
Every verdict arrives with its reasoning attached
A severity score tells you nothing you can act on. Cryvanta shows the events it correlated, the case it built, what it did — and exactly where it stopped and waited for a human.
Evidence
- 09:41:02process.createwinword.exe → powershell
- 09:41:02net.connect185.104.· · ·:443
- 09:41:03file.write%TEMP%\up1.dat
- 09:41:03registry.set…\Run\OneDriveSyncer
- 09:41:04process.createrundll32.exe up1.dat
PowerShell download cradle
T1059.001
Analyst reasoning
- Correlated 5 events on WKS-0413 within 2s
- Parent chain matches T1059.001 download cradle
- No change ticket, no maintenance window
- Host holds finance shares — blast radius high
The closed loop
Every attack we run teaches your defence to catch the next one
Offence informs defence. When our pentest fires a technique, the detection side learns to catch it — and every rule it produces is compile-checked and reviewed before it goes live.
- 01
Attack
Our pentest runs a real technique against your estate, under a scope you signed.
- 02
Observe
The endpoint sensor captures the telemetry the technique leaves behind, as normalised OCSF events.
- 03
Detect
The same Sigma engine runs on the endpoint and in the cloud, so rule semantics never drift between the two.
- 04
Reason
The AI analyst weighs the evidence and returns a verdict with its rationale, confidence and suggested action.
- 05
Harden
A new rule is drafted from the cluster, compile-checked, and queued for an operator to accept or reject.
Watch it
The whole loop, in thirty seconds
Then it starts again — and irreversible actions still hold for a human, by default.
An attacker only has to find one way through. Everything we learn finding it becomes something your defence already knows.
EU sovereignty
Your defence, kept in Europe
Regulation is moving fast, and most security stacks still route through US clouds and US models. Cryvanta is built the other way around.
NIS2
Scoped for the essential- and important-entity obligations landing across the EU.
DORA
Operational-resilience testing and monitoring for financial entities and their ICT providers.
GDPR & residency
Data stays in the EU. Erasure and retention controls are part of the platform, not paperwork.
Bring your own model
Point the analyst at an EU-hosted model — your sovereignty requirements, your choice.
Cryvanta is building toward SOC 2 and formal certification — we'll publish status rather than badges we haven't earned.
How we start
The first thing we do is talk.
No scope, no deck, no proposal. Half an hour on what you actually run and what is keeping you up — then we tell you what we would do about it, including if the answer is nothing yet.
A 30-minute call
What your estate actually looks like, what is already in place, and what is worrying you. Nothing to prepare and nothing to install.
We say what we'd do
And what we wouldn't. If a pentest is not the right first move for you, we will say so — it is a short conversation either way.
A written scope
Nothing is touched, tested or deployed until you have agreed the targets, the rules of engagement and the timing in writing.
The work, then a debrief
A prioritised report your engineers can act on and your board can read, walked through live rather than emailed over.
Who you'll be talking to
The people on the call are the people doing the work
No sales layer between the first conversation and the founders and delivery team closest to the work.

Offence
Robin Österdal
Founder & CEO
Leads the pentest work. Thinks like an attacker and explains the result without hiding behind a scanner report.

Defence
Malthe Bang Norengaard
Co-founder & CTO
Builds the technology — the endpoint sensor, the detection pipeline, the AI analyst, and the platform underneath them.

Board
Henrik Andersson
Board member · Company & Customer Delivery
Nearly 30 years in Swedish IT consulting — took a data and analytics firm from its founding year through to acquisition.
Where we actually are
Everything here is either shipping or labelled
Most security vendors round up. We don't — in security, being caught overstating costs more than the feature was worth. What is live is genuinely live and running against real estates; what is ahead is marked ahead. You will never have to guess which.
Capability
4 live · 4 ahead
- PenTest engagements for EU / Nordic organisationsLive
- Windows endpoint sensor + cloud detection pipelineLive
- AI analyst: triage, investigation and verdictsLive
- Multi-tenant console, GDPR erasure & retentionLive
- macOS and Linux endpoint sensorsAhead
- General availability beyond design partnersAhead
- SOC 2 and independent certificationAhead
- Self-service tenant onboardingAhead
Find the gaps, then watch them
Start with half an hour on what you actually run. From there it might be a pentest, the AI SOC early-access programme, or nothing yet — we will tell you which. A real person replies.